Description
UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.
Published: 2026-09-09
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Secure boot bypass via UEFI shell execution
Action: Immediate patch
AI Analysis

Impact

The vulnerability resides in the UEFI BIOS embedded shell of Insyde Software’s InsydeH2O firmware. It allows an attacker to execute shell commands or startup scripts that can override the secure boot validation process. This bypass permits the booting of unauthorized firmware or malware, effectively compromising the authenticity of the firmware and the integrity of the system’s boot chain. The weakness is classified as CWE-489, implying that code or command generation is improperly controlled.

Affected Systems

System owners of InsydeH2O firmware that have not applied the recent firmware updates are affected. The vendor’s official fix is available for Kernel 5.3 in firmware 05.3A.25, Kernel 5.4 in firmware 05.48.25, Kernel 5.5 in firmware 05.56.25, and Kernel 5.6 in firmware 05.63.25. Any prior firmware reflecting earlier kernel versions remains vulnerable.

Risk and Exploitability

The CVSS score of 8.2 reflects the high severity of this issue. EPSS data is not currently available, so the exact likelihood of exploitation cannot be quantified, but the lack of a KEV listing does not diminish the urgency. The likely attack vector appears to require local interaction with the UEFI environment, such as physical access or control over the boot configuration. Once the embedded shell is abused, an attacker can persistently install malicious code at the firmware level, undermining all subsequent security controls.

Generated by OpenCVE AI on September 9, 2026 at 11:23 UTC.

Remediation

Vendor Solution

Kernel 5.3: Version 05.3A.25 Kernel 5.4: Version 05.48.25 Kernel 5.5: Version 05.56.25 Kernel 5.6: Version 05.63.25


OpenCVE Recommended Actions

  • Apply the vendor-provided firmware update corresponding to your kernel version (e.g., use firmware 05.3A.25 for Kernel 5.3, 05.48.25 for Kernel 5.4, 05.56.25 for Kernel 5.5, or 05.63.25 for Kernel 5.6).
  • If updating the firmware is not immediately possible, disable the UEFI embedded shell from the BIOS setup or enforce restrictions that prevent execution of startup scripts.
  • Enable and enforce Secure Boot to reject all unsigned or unsigned firmware and operating‑system loaders, ensuring that only verified code can run during the boot process.

Generated by OpenCVE AI on September 9, 2026 at 11:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Insyde Software
Insyde Software insydeh2o
Vendors & Products Insyde Software
Insyde Software insydeh2o

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.
Title UEFI BIOS embedded Shell can be used to bypass Secure Boot
Weaknesses CWE-489
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Insyde Software Insydeh2o
cve-icon MITRE

Status: PUBLISHED

Assigner: Insyde

Published:

Updated: 2026-09-10T14:30:20.224Z

Reserved: 2026-04-17T06:07:42.556Z

Link: CVE-2026-6485

cve-icon Vulnrichment

Updated: 2026-09-10T14:30:15.507Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T04:19:36.437

Modified: 2026-09-10T15:17:39.427

Link: CVE-2026-6485

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T22:15:07Z

Weaknesses